feat: add server, workstation, and cloud edition manifests
Define the three flagship editions as plain-text manifests: - server (bastion): production server - observability stack, containers. - workstation (forge): curated KDE Plasma + dev toolchains. - cloud (nimbus): cloud kernel, cloud-init, guest agents. Each manifest carries metadata (services to enable/mask), a package list, a hardened kernel cmdline, and a btrfs fstab template.
This commit is contained in:
35
editions/server/kernel.cmdline
Normal file
35
editions/server/kernel.cmdline
Normal file
@@ -0,0 +1,35 @@
|
||||
# Arcline Server — kernel command line
|
||||
# Hardening flags + console config. Kept explicit and auditable.
|
||||
#
|
||||
# Security notes:
|
||||
# init_on_alloc / init_on_free — zero freshly allocated/freed memory
|
||||
# slab_nomerge — disable merging of similar slab objects
|
||||
# page_poison=1 — fill freed pages to catch use-after-free
|
||||
# pti=on — kernel page-table isolation
|
||||
# spectre_v2=on spec_store_bypass=on — mitigations on (no auto-off)
|
||||
# tsx=off — disable TSX (TAA mitigations)
|
||||
# lockdown=integrity — block unsigned kernel modifications
|
||||
# oops=panic panic=-1 — panic (and stay down) on oops
|
||||
# quiet loglevel=3 — quiet serial console boot
|
||||
|
||||
console=tty0
|
||||
console=ttyS0,115200n8
|
||||
quiet
|
||||
loglevel=3
|
||||
systemd.show_status=auto
|
||||
|
||||
# hardening
|
||||
init_on_alloc=1
|
||||
init_on_free=1
|
||||
slab_nomerge
|
||||
page_poison=1
|
||||
pti=on
|
||||
spectre_v2=on
|
||||
spec_store_bypass=on
|
||||
tsx=off
|
||||
lockdown=integrity
|
||||
oops=panic
|
||||
panic=-1
|
||||
|
||||
# btrfs / storage
|
||||
rootflags=subvol=@
|
||||
Reference in New Issue
Block a user